Security

Less data in the cloud. Fewer places to lose it.

ManaSplit is designed around short-lived transit, device-local conversation history, scoped persistent records, and explicit security boundaries. This page describes the approach without publishing a roadmap for attackers.

Transit

Queues, not archives

Realtime cloud state moves messages and coordinates calls. Delivery and hangup cleanup remove short-lived records, with server reapers for stale state.

Local

History on device

Messages, call history, downloaded media, and personal indexes are stored on your devices instead of becoming a permanent server-side conversation archive.

Persistent

Shared records are scoped

Profiles, groups, chat metadata, expenses, and settings use authenticated access controls tied to the person, group, chat, or device.

Encryption

Protected in motion and at rest

Supported messages use end-to-end encryption. Cloud traffic uses transport encryption, secrets live in managed secret stores, and enrolled security identities are encrypted with per-user data keys.

Devices

Linking needs proof

Companion devices use expiring pairing credentials, confirmation state, scoped authentication claims, and revocation controls.

AI

Rules own the decision

AI can explain evidence. Deterministic logic owns security severity and financial calculations. The app identifies on-device, private-cloud, and exact outputs.

Found something real? Tell us privately.

Email security@manasplit.app with the affected feature, impact, reproduction steps, and a safe proof. Do not access another person’s data, degrade the service, use social engineering, or publish an unpatched vulnerability.

We acknowledgeWe aim to confirm receipt within three business days.
We investigateWe will provide a tracking point and ask for details when needed.
We coordinateWe will discuss remediation and a reasonable disclosure date.